An Azure service that is used to provision Windows and Linux virtual machines.
Azure DC2s_v3 SGX: DCAP verification returns 0xA007 / INTEL-SA-00615 with MMIO mitigation warning
I am testing an Intel SGX enclave on an Azure VM and need clarification about the attestation result and platform mitigation requirements.
Environment:
- VM size: Standard_DC2s_v3
Region: East US
OS: Ubuntu 24.04.4 LTS
Kernel: 6.17.0-1022-azure
CPU reported by guest: Intel Xeon Platinum 8370C
Intel SGX SDK/PSW: 2.30.101.1
Intel DCAP quote verification library: 1.27.101.1
An SGX quote generated on the Azure VM was independently checked using Intel’s native Quote Verification Library on a separate machine.
Verification output:
Verification API call succeeded.
Collateral expiration status: 0
Quote verification result: 0xA007 (SGX_QL_QV_RESULT_SW_HARDENING_NEEDED)
Advisory: INTEL-SA-00615
The enclave’s MRENCLAVE and MRSIGNER match the signed build, and the quote’s DEBUG attribute is disabled. A modified quote was rejected. Our authorization policy currently blocks token issuance pending clarification of the conditional verification result.
Inside the Azure guest, this command: cat /sys/devices/system/cpu/vulnerabilities/mmio_stale_data
returns: “Vulnerable: Clear CPU buffers attempted, no microcode; SMT Host state unknown”
I understand that guest-visible CPU capabilities may not fully reflect physical-host mitigations. I am therefore seeking clarification rather than assuming the Azure host is unpatched.
Questions:
What host microcode, hypervisor mitigations, and SMT isolation assurances apply to DCsv3 VMs for INTEL-SA-00615?
Can this guest warning appear when the physical host is adequately mitigated?
What enclave software hardening must a relying party verify before accepting this specific 0xA007 result?
Is any Azure-supported configuration change or platform remediation required?
Could an Azure Confidential Computing / Intel SGX specialist advise? I can provide sanitized verification logs and build details if needed.I am testing an Intel SGX enclave on an Azure VM and need clarification about the attestation result and platform mitigation requirements.
Environment:
VM size: Standard_DC2s_v3
Region: East US
OS: Ubuntu 24.04.4 LTS
Kernel: 6.17.0-1022-azure
CPU reported by guest: Intel Xeon Platinum 8370C
Intel SGX SDK/PSW: 2.30.101.1
Intel DCAP quote verification library: 1.27.101.1
An SGX quote generated on the Azure VM was independently checked using Intel’s native Quote Verification Library on a separate machine.
Verification output:
Verification API call succeeded.
Collateral expiration status: 0
Quote verification result: 0xA007 (SGX_QL_QV_RESULT_SW_HARDENING_NEEDED)
Advisory: INTEL-SA-00615
The enclave’s MRENCLAVE and MRSIGNER match the signed build, and the quote’s DEBUG attribute is disabled. A modified quote was rejected. Our authorization policy currently blocks token issuance pending clarification of the conditional verification result.
Inside the Azure guest, this command:
cat /sys/devices/system/cpu/vulnerabilities/mmio_stale_data
returns:
“Vulnerable: Clear CPU buffers attempted, no microcode; SMT Host state unknown”
I understand that guest-visible CPU capabilities may not fully reflect physical-host mitigations. I am therefore seeking clarification rather than assuming the Azure host is unpatched.
Questions:
What host microcode, hypervisor mitigations, and SMT isolation assurances apply to DCsv3 VMs for INTEL-SA-00615?
Can this guest warning appear when the physical host is adequately mitigated?
What enclave software hardening must a relying party verify before accepting this specific 0xA007 result?
Is any Azure-supported configuration change or platform remediation required?
Could an Azure Confidential Computing / Intel SGX specialist advise? I can provide sanitized verification logs and build details if needed.